The hiring funnel has become an attack surface, and most security teams aren’t watching it. Mick Leach’s piece in SC Media walks through how North Korean operatives—and others—are bypassing background checks entirely by fabricating identities engineered to pass them. The FBI confirmed one made it into a federal agency; the U.N. estimates the broader scheme pulls in $250 million to $600 million annually. These aren’t disgruntled insiders misusing access. They’re adversaries who walked in the front door with credentials designed to look clean.
For cleared environments, the stakes are higher. A TS/SCI holder or someone working inside a SCIF isn’t just another remote developer—they’re sitting on the kind of access that can’t be clawed back once it’s granted. The vetting process for clearances is rigorous, but it still relies on documented history. If that history is fabricated well enough, it passes. Leach’s team at Abnormal flagged roughly 3,500 fraudulent applicants over 18 months using behavioral AI applied at the point of entry, surfacing patterns—recycled resumes, VoIP numbers, inconsistent geolocation—that don’t register as threats in isolation but reveal coordination when mapped across candidates.
The fix isn’t complicated, but it does require security teams to treat hiring the way they treat email or endpoint access: as a vector that needs active monitoring. That means getting into the workflow before onboarding, not after. For defense and intel contractors especially, where the margin for error is narrow and the consequences of a bad hire extend well beyond data loss, this isn’t optional anymore. If your security posture stops at the badge swipe, you’re already behind.